Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty
SD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF
Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections. The metric names were not checked for newli
Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked fo
Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.4
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Fina
rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allow
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1
Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences
A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injec
A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (C
eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsou
@fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only o
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final,
The HTTP Headers plugin for WordPress is vulnerable to CRLF Injection in all versions up to, and including, 1.19.2. This
PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communicati
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Fina
SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject
Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to
Gakido is a Python HTTP client focused on browser impersonation and anti-bot evasion. A vulnerability was discovered in
MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail
A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software
The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Improper Neutralizatio
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart construc
Netty allows request-line validation to be bypassed when a `DefaultHttpRequest` or `DefaultFullHttpRequest` is created f
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Response Split
Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values w
Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function
Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colon
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII con
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages wi
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to
MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not sanitize sender names c
Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unenco
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.11 before 18.7.6, 18.8 before 18.8.6, and 1
Rack is a modular Ruby web server interface. From version 3.2.0 to before version 3.2.6, Rack::Multipart::Parser unfolds
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject C
Mail content stored by a user can be crafted so that it is interpreted as dsync protocol commands when an administrator
ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject
A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplyi
A flaw was found in mod_proxy_cluster. This vulnerability, a Carriage Return Line Feed (CRLF) injection in the decodeen
iCalendar is a Ruby library for dealing with iCalendar files in the iCalendar format defined by RFC-5545. Starting in ve
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application us
WWBN AVideo is an open source video platform. In versions up to and including 29.0, the unauthenticated plugin/Scheduler
undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type he
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the CalDAV output generator builds iCale
Frequently Asked Questions
What is CWE-93?
CWE-93 (CWE-93) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-93?
There are 130 CVE records associated with CWE-93 in our database. Of these, 14 are critical severity, 37 are high severity, and 50 are medium severity.
How can I protect against CWE-93 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-93 using AI-powered security agents.
Detect CWE-93 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-93 vulnerabilities across your infrastructure.
Get Started